logo

Fog Ransomware 2025: Deep Dive into TTPs

ID: 5b8b36e9-910d-5854-a5b4-936105fd7f12

STIX ID: report--5b8b36e9-910d-5854-a5b4-936105fd7f12

Feed Name: Resources-2

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

The report analyzes the Fog ransomware campaign (first observed May 2024), describing a rapid evolution from low-tier targets to high-value attacks, a multi-stage infection chain (vulnerability exploitation including CVE-2024-40766 and CVE-2024-40711, credential compromise, phishing with PowerShell loaders), privilege escalation via an exploited Intel driver, extensive discovery and lateral movement using living-off-the-land tools, espionage-like surveillance (Syteca/Ekran, GC2, Adaptix), large-scale data exfiltration for double-extortion, backup destruction and robust hybrid encryption, and a TOR-based extortion/leak site; the report also maps detection and simulation recommendations via the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.